dd9d7cf9372a5737863d4dc33f132b9a.exe
Classification: Malicious
dd9d7cf9372a5737863d4dc33f132b9a.exe is a malicious file sample. Linked to Runningrat malware. Reported by 1 threat source, last seen 2024-09-27.
Detection summary
- 62 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: RUNNINGRAT (S0253)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| RunningRAT | MalwareBazaar Abuse.ch | 2024-09-27 09:00:27 | 2024-09-27 09:00:27 | malicious-activity | S0253 RunningRAT |
Sample information
- Filenames
- dd9d7cf9372a5737863d4dc33f132b9a.exe
- File type
- application/x-dosexec
- MD5
dd9d7cf9372a5737863d4dc33f132b9a- SHA-1
4380d4afc2786ee77d2644aa1e34c9b77951b5d3- SHA-256
bb46d0c8b43a92fda32622b15fd8060dedf1f0666c8e536cdad49ad3e1a79ade- First indexed
- 2024-09-27 10:20:33
- Last updated
- 2026-02-07 11:11:03
Antivirus detections
| Engine | Detection |
|---|---|
| APEX | Malicious |
| AVG | Win32:MalwareX-gen [Drp] |
| AhnLab-V3 | Trojan/Win32.Venik.R145444 |
| Alibaba | Backdoor:Win32/YoungLotus.a000f2a9 |
| Antiy-AVL | Trojan/Win32.Farfli |
| Arcabit | Trojan.RI.1 |
| Avast | Win32:MalwareX-gen [Drp] |
| Avira | HEUR/AGEN.1359651 |
| BitDefender | Gen:Heur.RI.1 |
| CAT-QuickHeal | Trojan.Younglotus.20397 |
| CTX | exe.trojan.younglotus |
| ClamAV | Win.Dropper.Gh0stRAT-7073897-1 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.DownLoader12.47777 |
| ESET-NOD32 | Win32/Farfli.BGW |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Heur.RI.1 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1359651 |
| Fortinet | W32/Farfli.BGW!tr |
| GData | Gen:Heur.RI.1 |
| Detected | |
| Gridinsoft | Trojan.Win32.Agent.vl!n |
| Ikarus | Trojan.Win32.Farfli |
| Jiangmin | Trojan/YoungLotus.e |
| K7AntiVirus | Trojan ( 0055e3e41 ) |
| K7GW | Trojan ( 0055e3e41 ) |
| Kaspersky | Trojan.Win32.YoungLotus.t |
| Kingsoft | Win32.Trojan.YoungLotus.t |
| Lionic | Trojan.Win32.YoungLotus.tsAS |
| Malwarebytes | Malware.AI.4194114185 |
| MaxSecure | Trojan.Malware.8167493.susgen |
| McAfeeD | ti!BB46D0C8B43A |
| MicroWorld-eScan | Gen:Heur.RI.1 |
| Microsoft | Backdoor:Win32/Venik!pz |
| NANO-Antivirus | Trojan.Win32.YoungLotus.dpanmc |
| Paloalto | generic.ml |
| Panda | Trj/Genetic.gen |
| Rising | Backdoor.Farfli!1.C639 (CLASSIC) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Zusy |
| Sangfor | Backdoor.Win32.Farfli.Viov |
| Skyhigh | BackDoor-FCWQ!DD9D7CF9372A |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Malware.Win32.Gencirc.10b39405 |
| Trapmine | malicious.moderate.ml.score |
| TrellixENS | BackDoor-FCWQ!DD9D7CF9372A |
| TrendMicro | BKDR_ZEGOST.SM29 |
| TrendMicro-HouseCall | BKDR_ZEGOST.SM29 |
| VBA32 | BScope.Backdoor.Caphaw |
| VIPRE | Gen:Heur.RI.1 |
| Varist | W32/S-0f55ee81!Eldorado |
| VirIT | Backdoor.Win32.Generic.JUY |
| Webroot | Trojan.Younglotus |
| Xcitium | TrojWare.Win32.YoungLotus.TCM@5ruomd |
| Yandex | Trojan.GenAsa!BZKdUv1dR3c |
| Zillya | Trojan.YoungLotus.Win32.88 |
| Zoner | Trojan.Win32.97590 |
| alibabacloud | Backdoor:Win/Farfli |
| huorong | Backdoor/Farfli.bn |